VYPR
breachPublished Aug 11, 2026· 1 source

Ransomware Disrupts Industrial Production by Targeting IT Systems, Not Just OT

Dragos reports a 12% increase in ransomware incidents targeting industrial organizations in Q2 2026, highlighting that attackers can halt production by compromising IT systems without needing direct access to operational technology.

Ransomware attacks continue to pose a significant threat to industrial organizations, with a notable 12% increase in incidents reported in the second quarter of 2026 compared to the previous quarter, according to a new analysis by Dragos. The cybersecurity firm identified 1,140 ransomware incidents affecting industrial entities, underscoring a persistent and evolving threat landscape. This rise indicates that attackers are increasingly finding success by targeting the enterprise IT systems that underpin operational technology (OT) environments, rather than solely focusing on direct access to industrial control systems (ICS).

The manufacturing sector remains the most heavily impacted, accounting for 65% of all reported incidents with 747 cases. Other significantly affected sectors include construction (176 incidents), equipment manufacturing (114), and food and beverage (70). Organizations that support ICS environments, such as engineering firms and system integrators, also experienced a substantial number of attacks, with 117 incidents reported. Transportation and logistics sectors were also targeted, with 95 incidents.

Dragos researchers Lexie Mooney and Abdulrahman H. Alamri emphasized that the risk to industrial organizations is increasingly shaped by adversaries' focus on IT systems. Disrupting critical IT platforms like Enterprise Resource Planning (ERP) systems, virtualization infrastructure, identity services, and remote access gateways can rapidly lead to production shutdowns and significant supply chain impacts. This strategic shift means that even without direct access to OT, attackers can achieve their disruptive goals.

A case in point is the incident at Mackay Sugar, Australia's second-largest raw sugar producer. Following a cyberattack on June 10, the company was forced to halt milling and cane haulage at two of its three mills. While one mill eventually resumed limited manual operations, the Gentlemen ransomware group claimed responsibility. Dragos's analysis found no evidence that the attackers gained access to ICS or directly manipulated OT, suggesting the disruption stemmed primarily from the compromise of enterprise IT systems or subsequent containment measures.

Furthermore, the report highlights a continuing trend where extortion is shifting away from file encryption towards data theft. This means that even after affected systems are restored, organizations remain vulnerable as stolen employee, customer, supplier, financial, or operational data can be published or used for further extortion. Attackers are consistently gaining initial access through internet-facing devices, compromised remote management tools, and stolen credentials.

Several ransomware groups were particularly active in Q2 2026. Qilin affiliates, who gained access through compromised credentials and vulnerable internet-facing infrastructure, logged the highest number of industrial victim claims with 140 incidents, though this was a decrease from Q1. Akira followed with 129 incidents, often leveraging compromised VPN devices, while The Gentlemen group saw an increase, reporting 125 incidents after targeting edge devices.

Social engineering tactics have also evolved, with attackers increasingly impersonating internal IT support on enterprise collaboration platforms like Microsoft Teams. They guide targets through screen-sharing sessions to install remote monitoring tools. Additionally, attackers are creating credential-harvesting domains that mimic victim organizations' naming conventions to capture passwords and multi-factor authentication (MFA) codes. The FBI has also noted instances where ransomware operatives physically infiltrate offices, posing as IT technicians.

Law enforcement agencies continue to disrupt ransomware operations. An international operation dismantled the First VPN anonymization service, and Operation Endgame targeted malware families like SocGholish and Amadey, recovering millions of stolen credentials. Geographically, North America remains the top target, with 514 incidents, followed by Europe with 316. The US alone accounted for 431 incidents. Dragos advises organizations to assume all internet-facing assets are discoverable and actively sought by adversaries, making continuous external attack surface management essential.

Synthesized by Vypr AI